Impact
The vulnerability is a stack-based buffer overflow in the function AdvSetLanip of the httpd/netctrl component. By manipulating the GetValue/SetValue arguments, a remote attacker can trigger an overflow, potentially allowing execution of arbitrary code on the device. The CVSS score of 8.7 signals a high severity, indicating significant risk if exploited. The description notes that the exploit has been made public and could be used against vulnerable units.
Affected Systems
This flaw affects Tenda AC10 routers running firmware version 16.03.10.09_multi_TDE01. The exposed endpoint is /goform/AdvSetLanip within the httpd/netctrl interface. No other models or firmware versions are listed as affected, so the impact is limited to devices with that specific firmware build.
Risk and Exploitability
The exploit is remote and requires no local privileges. The EPSS score of <1% indicates a low likelihood of exploitation, but the public availability of exploit code suggests that attackers could still target these routers. The vulnerability is not listed in the CISA KEV catalog, though the high CVSS score and publicly disclosed exploit emphasize that exposed devices remain at risk.
OpenCVE Enrichment